CVE List
Id | CVE No. | Status | Description | Phase | Votes | Comments | Actions |
---|---|---|---|---|---|---|---|
91373 | CVE-2016-4554 | Candidate | mime_header.cc in Squid before 3.5.18 allows remote attackers to bypass intended same-origin restrictions and possibly conduct cache-poisoning attacks via a crafted HTTP Host header, aka a "header smuggling" issue. | Assigned (20160506) | None (candidate not yet proposed) | View | |
26093 | CVE-2007-2736 | Candidate | PHP remote file inclusion vulnerability in index.php in Achievo 1.1.0 allows remote attackers to execute arbitrary PHP code via a URL in the config_atkroot parameter. | Assigned (20070517) | None (candidate not yet proposed) | View | |
91629 | CVE-2016-4810 | Candidate | Citrix Studio before 7.6.1000, Citrix XenDesktop 7.x before 7.6 LTSR Cumulative Update 1 (CU1), and Citrix XenApp 7.5 and 7.6 allow attackers to set Access Policy rules on the XenDesktop Delivery Controller via unspecified vectors. | Assigned (20160517) | None (candidate not yet proposed) | View | |
26349 | CVE-2007-2992 | Candidate | Multiple SQL injection vulnerabilities in OmegaMw7.asp in OMEGA (aka Omegasoft) INterneSErvicesLosungen (INSEL) allow remote attackers to execute arbitrary SQL commands via (1) user-created text fields; the (2) F05003, (3) F05005, and (4) F05015 fields; and other unspecified standard fields. | Assigned (20070604) | None (candidate not yet proposed) | View | |
91885 | CVE-2016-5066 | Candidate | Sierra Wireless GX 440 devices with ALEOS firmware 4.3.2 have weak passwords for admin, rauser, sconsole, and user. | Assigned (20160526) | None (candidate not yet proposed) | View |
Page 19460 of 20943, showing 5 records out of 104715 total, starting on record 97296, ending on 97300